STIGQter STIGQter: STIG Summary: Microsoft Windows Server 2022 Security Technical Implementation Guide Version: 2 Release: 9 Benchmark Date: 01 Jul 2026:

Windows Server 2022 systems requiring data-at-rest protections must employ cryptographic mechanisms to prevent unauthorized disclosure and modification of the information at rest.

DISA Rule

SV-254262r1210265_rule

Vulnerability Number

V-254262

Group Title

SRG-OS-000185-GPOS-00079

Rule Version

WN22-00-000250

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

Configure systems that require data-at-rest protections to employ encryption to protect the confidentiality and integrity of all persistent user-generated data and operating system-specific configuration data.

The encryption method implemented must use FIPS-compliant algorithms.

Check Contents

Verify systems that require additional protections due to factors such as inadequate physical protection or sensitivity of the data employ encryption to protect the confidentiality and integrity of all information at rest.

Note: If there is a documented and approved reason to omit data-at-rest encryption at the operating system level, such as encryption provided by a hypervisor or a disk storage array in a virtualized environment, this requirement is not applicable.

If there is no evidence that persistent user-generated data and operating system-specific configuration data are encrypted, this is a finding.

Vulnerability Number

V-254262

Documentable

False

Rule Version

WN22-00-000250

Severity Override Guidance

Verify systems that require additional protections due to factors such as inadequate physical protection or sensitivity of the data employ encryption to protect the confidentiality and integrity of all information at rest.

Note: If there is a documented and approved reason to omit data-at-rest encryption at the operating system level, such as encryption provided by a hypervisor or a disk storage array in a virtualized environment, this requirement is not applicable.

If there is no evidence that persistent user-generated data and operating system-specific configuration data are encrypted, this is a finding.

Check Content Reference

M

Target Key

5485